Security & Data Practices
Plain answers about how this website and our engagements handle your information.
Security questions deserve direct answers, especially from a firm that works with public-sector teams. This page describes our current practices in plain language — and is explicit about what we do not claim.
Last reviewed August 15, 2026
This website
The site is served over HTTPS with security headers enabled. The only information it collects is what you type into the contact form: name, organization, email, organization type, and message. Submissions are validated and rate-limited server-side, delivered by email through Brevo (our transactional email provider), and are not stored in a website database. There are no advertising trackers. See the privacy policy for details.
In client engagements
Client data stays in client systems: we build integrations that connect the tools you already run rather than copying your records into ours. Access is scoped to what a workflow actually needs, credentials are exchanged through your systems rather than email, and staff review is kept in place for sensitive or high-impact steps. Workflows are documented so your team can see — and audit — exactly what moves where.
AI-specific practices
When an engagement uses AI services, we identify which data reaches which provider before anything is built, prefer configurations that do not use your data for model training, and design workflows so that a human reviews AI output wherever it affects a customer, resident, or record of consequence.
What we do not claim
Banyan does not currently hold formal certifications such as SOC 2 or ISO 27001, and we will not imply otherwise. If your procurement process requires specific attestations, tell us early — we will state plainly what we can and cannot satisfy, and scope the engagement accordingly.
Reporting a concern
To report a security concern about this website, email hello@banyanaiconsulting.com. Reports are read promptly and taken seriously.